CVE-2023-53993
published 2025-12-24CVE-2023-53993: In the Linux kernel, the following vulnerability has been resolved: PCI/DOE: Fix memory leak with CONFIG_DEBUG_OBJECTS=y After a pci_doe_task completes, its…
PriorityP414low5.5
EPSS
0.18%
7.5th percentile
In the Linux kernel, the following vulnerability has been resolved:
PCI/DOE: Fix memory leak with CONFIG_DEBUG_OBJECTS=y
After a pci_doe_task completes, its work_struct needs to be destroyed
to avoid a memory leak with CONFIG_DEBUG_OBJECTS=y.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.25-1 (bookworm) | linux 6.1.25-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 9d24322e887b6a3d3f9f9c3e76937a646102c8c1 < 2a0e0f4773fe8032fb17e56f897bee32ce3cdc2b | 2a0e0f4773fe8032fb17e56f897bee32ce3cdc2b |
| linux | linux | >= 9d24322e887b6a3d3f9f9c3e76937a646102c8c1 < 95628b830952943631d3d74f73f431f501c5d6f5 | 95628b830952943631d3d74f73f431f501c5d6f5 |
| linux | linux | >= 9d24322e887b6a3d3f9f9c3e76937a646102c8c1 < abf04be0e7071f2bcd39bf97ba407e7d4439785e | abf04be0e7071f2bcd39bf97ba407e7d4439785e |
| linux | linux_kernel | >= 0 < 6.1.25-1 | 6.1.25-1 |
| linux | linux_kernel | >= 0 < 6.1.25-1 | 6.1.25-1 |
| linux | linux_kernel | >= 0 < 6.1.25-1 | 6.1.25-1 |
| linux | linux_kernel | >= 6.0.0 < 6.1.24 | 6.1.24 |
| linux | linux_kernel | >= 6.2.0 < 6.2.11 | 6.2.11 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: Kernel: Denial of Service due to memory leak in PCI/DOE
vendor_redhat·2025-12-24·CVSS 5.5
CVE-2023-53993 [LOW] CWE-772 kernel: Kernel: Denial of Service due to memory leak in PCI/DOE
kernel: Kernel: Denial of Service due to memory leak in PCI/DOE
In the Linux kernel, the following vulnerability has been resolved:
PCI/DOE: Fix memory leak with CONFIG_DEBUG_OBJECTS=y
After a pci_doe_task completes, its work_struct needs to be destroyed
to avoid a memory leak with CONFIG_DEBUG_OBJECTS=y.
A flaw was found in the Linux kernel. A local attacker with low privileges could exploit a memory leak vulnerability in the PCI-e Data Object Exchange (PCI/DOE) subsystem. This occurs when a PCI/DOE task completes, but its associated work structure is not properly destroyed, leading to a continuous accumulation of memory. This can result in a Denial of Service (DoS) due to resource exhaustion.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterp
Debian
CVE-2023-53993: linux - In the Linux kernel, the following vulnerability has been resolved: PCI/DOE: Fi...
vendor_debian·2023
CVE-2023-53993 CVE-2023-53993: linux - In the Linux kernel, the following vulnerability has been resolved: PCI/DOE: Fi...
In the Linux kernel, the following vulnerability has been resolved: PCI/DOE: Fix memory leak with CONFIG_DEBUG_OBJECTS=y After a pci_doe_task completes, its work_struct needs to be destroyed to avoid a memory leak with CONFIG_DEBUG_OBJECTS=y.
Scope: local
bookworm: resolved (fixed in 6.1.25-1)
bullseye: resolved
forky: resolved (fixed in 6.1.25-1)
sid: resolved (fixed in 6.1.25-1)
trixie: resolved (fixed in 6.1.25-1)
OSV
CVE-2023-53993: In the Linux kernel, the following vulnerability has been resolved: PCI/DOE: Fix memory leak with CONFIG_DEBUG_OBJECTS=y After a pci_doe_task complete
osv·2025-12-24
CVE-2023-53993 CVE-2023-53993: In the Linux kernel, the following vulnerability has been resolved: PCI/DOE: Fix memory leak with CONFIG_DEBUG_OBJECTS=y After a pci_doe_task complete
In the Linux kernel, the following vulnerability has been resolved: PCI/DOE: Fix memory leak with CONFIG_DEBUG_OBJECTS=y After a pci_doe_task completes, its work_struct needs to be destroyed to avoid a memory leak with CONFIG_DEBUG_OBJECTS=y.
OSV
PCI/DOE: Fix memory leak with CONFIG_DEBUG_OBJECTS=y
osv·2025-12-24
CVE-2023-53993 PCI/DOE: Fix memory leak with CONFIG_DEBUG_OBJECTS=y
PCI/DOE: Fix memory leak with CONFIG_DEBUG_OBJECTS=y
In the Linux kernel, the following vulnerability has been resolved:
PCI/DOE: Fix memory leak with CONFIG_DEBUG_OBJECTS=y
After a pci_doe_task completes, its work_struct needs to be destroyed
to avoid a memory leak with CONFIG_DEBUG_OBJECTS=y.
GHSA
GHSA-4vfj-wgm2-99m2: In the Linux kernel, the following vulnerability has been resolved:
PCI/DOE: Fix memory leak with CONFIG_DEBUG_OBJECTS=y
After a pci_doe_task comple
ghsa_unreviewed·2025-12-24
CVE-2023-53993 GHSA-4vfj-wgm2-99m2: In the Linux kernel, the following vulnerability has been resolved:
PCI/DOE: Fix memory leak with CONFIG_DEBUG_OBJECTS=y
After a pci_doe_task comple
In the Linux kernel, the following vulnerability has been resolved:
PCI/DOE: Fix memory leak with CONFIG_DEBUG_OBJECTS=y
After a pci_doe_task completes, its work_struct needs to be destroyed
to avoid a memory leak with CONFIG_DEBUG_OBJECTS=y.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2023-53993 kernel: Kernel: Denial of Service due to memory leak in PCI/DOE
bugzilla·2025-12-24
CVE-2023-53993 [LOW] CVE-2023-53993 kernel: Kernel: Denial of Service due to memory leak in PCI/DOE
CVE-2023-53993 kernel: Kernel: Denial of Service due to memory leak in PCI/DOE
In the Linux kernel, the following vulnerability has been resolved:
PCI/DOE: Fix memory leak with CONFIG_DEBUG_OBJECTS=y
After a pci_doe_task completes, its work_struct needs to be destroyed
to avoid a memory leak with CONFIG_DEBUG_OBJECTS=y.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025122424-CVE-2023-53993-7ec2@gregkh/T
Wiz
CVE-2023-53993 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2023-53993 CVE-2023-53993 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2023-53993 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
PCI/DOE: Fix memory leak with CONFIG_DEBUG_OBJECTS=y
After a pci_doe_task completes, its work_struct needs to be destroyed
to avoid a memory leak with CONFIG_DEBUG_OBJECTS=y.
Source : NVD
Published December 24, 2025
CNA Score N/A
Affected Technologies
Linux Kernel
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 6.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
perf
bpftool
Sources
NVD
Debian 12, 13, 14 Has Fix Added at: Dec 26, 2025
Echo Has Fix Added at: Dec 26, 2025
Red Hat 9 Severity LOW Has Fix Added at:
2025-12-24
Published